Josh Ross
Co-Founder & CEO of Ironloop
New York City, New York, United States
Actions
Josh Ross is the Co-Founder & CEO of Ironloop, a cybersecurity startup helping manufacturing, energy, and defense keep operations secure and audit-ready. Ironloop turns industrial machine and network configurations into a continuously updated inventory, change alerts, and compliance-ready documentation, so teams can reduce risk without disrupting production. Before Ironloop, Josh led cloud infrastructure at Applied Intuition, where he built deployment automation, monitoring, and observability systems across cloud and on-prem environments, including government and defense networks. He holds a degree in computer science and economics from the University of Pennsylvania and is based in New York City.
Area of Expertise
Topics
Target Rich, Cyber Poor: Raising the OT Security Baseline As Attacks Get Cheaper
Most OT security guidance is written for organizations that don't exist: well-staffed, well-funded teams with mature programs. The reality for much of critical infrastructure is the opposite. A water district, a rural cooperative, or a regional manufacturer often runs critical processes with a handful of people and a fraction of the baseline controls that frameworks assume. These operators have long been protected less by their defenses than by a simple fact: they weren't worth the effort to attack.
That protection is eroding. As the marginal cost of a capable attack falls, the economics of target selection change with it. Reconnaissance, social engineering, and exploitation are all getting cheaper, and when attacking gets cheaper, attackers cast a wider net. Operators who used to sit below the threshold of attention increasingly won't.
This session makes the case that the right response is not the advanced, expensive tooling the market tends to sell, but getting the fundamentals right first. We'll walk through what a right-sized OT security baseline actually looks like for a resource-constrained operator, including a pragmatic take on defense in depth that fits real staffing and budgets.
We'll then look at how open-source tooling can help teams raise that baseline at little or no cost, focusing on the structural building blocks rather than specific product picks, and being honest about where the gaps are. Attendees will leave with a way to reason about sequencing and spend on their own terms.
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top